Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Compliance GitHub Repositories
Explore popular GitHub repositories tagged “compliance”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment. Connect your agents now and build on the Agentic Cloud Defender.
Open Policy Agent (OPA) is an open source, general-purpose policy engine.
immudb - immutable database based on zero trust, SQL/Key-Value/Document model, tamperproof, data change history
Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Unified Policy as Code
Tfsec is now part of Trivy
Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.
Open Source Cloud Native Application Protection Platform (CNAPP)
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Personal, Enterprise, Government and Military security levels | SLSA Level 3 Compliant for Secure Development and Build Process | Apps Available on MS Store✨
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 150+ global frameworks with automatic control mapping, including ISO 27001, NIST CSF, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, CMMC, and more.
A FAST Kubernetes manifests validator, with support for Custom Resources!
InSpec: Auditing and Testing Framework
Security automation content in SCAP, Bash, Ansible, and other formats
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
HardeningKitty and Windows Hardening Settings
macOS Security Compliance Project
Open-source infrastructure and data orchestration platform for risk decisioning
Pre-submission compliance scanner for the Apple App Store and Google Play. Scans code, privacy manifests, Android manifests, and IPA/APK/AAB binaries against the review guidelines. Offline, no account.
Open-source, self-hosted file-processing tool. Convert, compress, OCR, transcribe & run local AI across image, video, audio, PDF & documents, via UI, REST API & pipelines. Your files never leave your network.
The Enterprise Architecture Governance Harness — strategy, architecture, delivery, and assurance using AI coding assistants
A suite of tools to automate software compliance checks.
AI Native platform to get companies compliant - Vanta & Drata Alternative
NIST Certified SCAP 1.2 toolkit
Appshark is a static taint analysis platform to scan vulnerabilities in an Android app.
🧵 CLI tool for directly patching container images!
Compliance automation framework, focused on SOC2